Hi,
I've a corporate laptop that uses Forticlient to establish a VPN
connection to corporate resources.
When working at home, when this corporate laptop is connected through the ISP
router, there's no problem connecting to the VPN server.
Now, I'm setting up my own router/firewall.
Using simple NAT rules, other systems can connect fine to the Internet, also the corporate
laptop can connect fine for everything except the VPN resources.
When I try to connect the VPN, Forticlient 2.7.8.1140 returns:
"a network error prevented updates from being downloaded".
It seems that for this kind of ssl vpn there are some special rules.
Can you please tell me what rules, protocols, ports, etc should I
consider in my router/firewall?
If you could show Linux iptables rules (or FreeBSD, OpenBSD, NetBSD equivalents), it would be very kind of you.
Thank you
Hi
No special rule needed, except need to open the outgoing connection to the remote SSL VPN server IP:port (usually TCP 443 or 10443).
NAT is fully supported.
@netvpn15 wrote:Hi,
I've a corporate laptop that uses Forticlient to establish a VPN
connection to corporate resources.
When working at home, when this corporate laptop is connected through the ISP
router, there's no problem connecting to the VPN server.
Now, I'm setting up my own router/firewall.
Using simple NAT rules, other systems can connect fine to the Internet, also the corporate
laptop can connect fine for everything except the VPN resources.
When I try to connect the VPN, Forticlient 2.7.8.1140 returns:
"a network error prevented updates from being downloaded".
It seems that for this kind of ssl vpn there are some special rules.
Can you please tell me what rules, protocols, ports, etc should I
consider in my router/firewall?If you could show Linux iptables rules (or FreeBSD, OpenBSD, NetBSD equivalents), it would be very kind of you.
Thank you
@netvpn15 wrote:Hi,
I've a corporate laptop that uses Forticlient to establish a VPN
connection to corporate resources.
When working at home, when this corporate laptop is connected through the ISP
router, there's no problem connecting to the VPN server.
Now, I'm setting up my own router/firewall.
Using simple NAT rules, other systems can connect fine to the Internet, also the corporate
laptop can connect fine for everything except the VPN resources.
When I try to connect the VPN, Forticlient 2.7.8.1140 returns:
"a network error prevented updates from being downloaded".
It seems that for this kind of ssl vpn there are some special rules.
Can you please tell me what rules, protocols, ports, etc should I
consider in my router/firewall?If you could show Linux iptables rules (or FreeBSD, OpenBSD, NetBSD equivalents), it would be very kind of you.
Thank you
Maybe there's some problem because of IPv6?
My filter table is all about IPv4:
@netvpn15 wrote:Hi,
I've a corporate laptop that uses Forticlient to establish a VPN
connection to corporate resources.
When working at home, when this corporate laptop is connected through the ISP
router, there's no problem connecting to the VPN server.
Now, I'm setting up my own router/firewall.
Using simple NAT rules, other systems can connect fine to the Internet, also the corporate
laptop can connect fine for everything except the VPN resources.
When I try to connect the VPN, Forticlient 2.7.8.1140 returns:
"a network error prevented updates from being downloaded".
It seems that for this kind of ssl vpn there are some special rules.
Can you please tell me what rules, protocols, ports, etc should I
consider in my router/firewall?If you could show Linux iptables rules (or FreeBSD, OpenBSD, NetBSD equivalents), it would be very kind of you.
Thank you
Do you find anything wrong? This is not even blocking anything.
Tried with
net.inet6.ip6.forwarding = 0
and also
net.inet6.ip6.forwarding = 1
IPv4 is set for forwarding: net.inet.ip.forwarding = 1
User | Count |
---|---|
2587 | |
1380 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.